If by saying “unwanted” you mean that packets from WLAN are forwarded to the LAN, then yes you have to add some deny rules in the FORWARD chain of the firewall. By default it is set to allow all forwarding traffic.